Live Session

Ransomware Response — Exercise Alpha

Facilitator-led incident response simulation. Your security team trains against realistic attack scenarios with role-based exercises, deterministic scoring, and full after-action analysis.

Elapsed
42:18
Start Training
Event Stream
14:32:07SIEMBrute-force attempt on VPN gateway — 847 failed auths in 90s
14:32:12EDRSuspicious PowerShell execution on WS-0147
14:32:18FWOutbound connection to known C2 IP 198.51.100.23
Role Performance
RoleStatusActionsScoreTrend
Incident Commanderactive1487+12
SecOps Analystactive2391+8
IT Operationsactive1172-3
Communicationsidle668+5
Legal Counselidle454-7
Executiveactive879+2
Session Metrics
Team Score
78.4/100
Injects Fired
12/18
Actions Taken
66total
Ops Budget
42%remaining
Response Time (min)
Detection
4
Contain
18
Escalation
8
Recovery
27
Comms
22
Threat Coverage
91%Detection
72%Containment
58%Recovery
Active Inject
Ransomware encryption spreading to backup servers
Awaiting team response — 03:42 since inject
Platform Capabilities

Everything your team needs to train like it's real.

Mission Control gives facilitators full control over realistic simulations — with deterministic engines, role-based scoring, and structured after-action review.

Facilitator Console

See all player actions in real-time. Trigger injects, override actions, adjust difficulty. Full session control without breaking immersion.

18inject types supported

Role-Based Exercises

Six distinct roles with unique views and actions: IC, SecOps, IT Ops, Comms, Legal, Executive. Each mirrors real-world organizational silos.

6concurrent roles

Scenario Engine

Deterministic simulation — same inputs, same outputs. Build custom network topologies, threat actor models, and branching inject timelines.

100%reproducible runs

Transparent Scoring

Every point traces to a specific action, timing decision, or evidence link. Per-role breakdowns with trend analysis across sessions.

340+scoring criteria

After-Action Reports

Full event timeline, score breakdowns, business impact analysis, and improvement recommendations. Incident documentation graded against rubrics.

12report sections

Readiness Analytics

Track team performance across exercises. Identify recurring gaps, measure improvement velocity, and build a data-driven training program.

87%avg readiness lift
Scenario Library

Pre-built and custom scenarios for every threat model.

Choose from a library of realistic attack scenarios or author your own with custom topologies, inject timelines, and scoring rubrics.

ScenarioCategoryDifficultyRolesDurationSessions Run
Ransomware OutbreakRansomware
690 min1,247
APT Lateral MovementAPT
6120 min834
Insider Data ExfilInsider Threat
575 min612
Supply Chain CompromiseSupply Chain
6150 min423
Cloud MisconfigurationCloud Security
460 min956
BEC Wire FraudSocial Engineering
590 min578
Platform Metrics

Measured readiness, not checkbox compliance.

4,200+
Exercises completed
across 340 organizations
87%
Readiness improvement
avg after 3 exercises
23 min
Faster MTTR
mean time to respond
6
Concurrent roles
per simulation session
Avg team score by exercise count
1st exercise
52
2nd exercise
67
3rd exercise
78
4th exercise
84
5th exercise
89
Gap categories identified
Communication
89
Escalation
76
Evidence
71
Containment
64
Documentation
58
Recovery
43
Pricing

Start free. Scale when ready.

Starter
Free

One team, pre-built scenarios, up to 6 participants.

3 pre-built scenarios
Up to 6 participants
Full AAR reports
Drill mode
Get started
Team
$49/seat/mo

Custom scenarios, unlimited participants, org analytics.

Unlimited scenarios
Scenario authoring
Up to 50 participants
SSO & org mgmt
Readiness analytics
Start free trial

Find the gaps before an adversary does.

Your first exercise is free. Set up in five minutes. No credit card, no sales call.